TKM Group FZE
Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
Trade licence: 4203780.01
Responsible data-processing contact: Nicklas Christensen · info@replygate.io
1. Parties and agreement
This Data Processing Agreement (DPA) forms part of the service agreement between TKM Group FZE (TKM, Replygate, we or us) and the legal organisation identified in the account or Order Form through which its authorised representative accepts the agreement (Customer or you). It applies to personal data we process on your behalf through the agreed Service (Customer Personal Data).
You act as controller and we act as processor. If you act as a processor for another controller, the relevant processor-to-processor arrangements must be agreed before that processing begins. Data-protection terms have the meanings given in the GDPR where applicable.
This DPA includes its schedules, the incorporated account agreement record and applicable Standard Contractual Clauses (SCCs) under Schedule 4. An authorised representative accepts the standard agreement electronically when signing up or through the account agreement confirmation. The linked agreement version is available before acceptance and is retained with the acceptance record. Any outstanding party particulars and applicable SCC execution requirements must be completed before the affected processing or transfer begins. No separate paper form is required.
Applicable mandatory law and SCCs prevail over conflicting provisions, followed by this DPA and then the Terms of Service and Order Forms. Commercial exclusions, liability limits and forum provisions do not restrict mandatory or SCC rights.
2. Your instructions and permitted purposes
We process Customer Personal Data only on your documented instructions to provide the agreed Service, including instructions about international transfers. Instructions comprise this DPA, the agreed features and connection settings, and lawful instructions from authorised Customer contacts. Schedule 1 describes the processing.
If Union or Member State law applicable to us requires processing under Article 28(3)(a) GDPR, we will inform you before processing unless that law prohibits notification on important public-interest grounds. Applicable SCC duties remain unaffected. We will immediately inform you if we consider an instruction to infringe applicable data-protection law and suspend the affected instruction where necessary pending resolution.
You are responsible for your lawful basis, any additional condition for processing health information, notices to individuals and the lawfulness of your instructions. We remain responsible for our own obligations. Acceptance of this DPA is not consent from patients or other individuals.
For the agreed clinic correspondence service, an authorised clinic user reviews AI drafts, recipients and appropriateness before sending. Clinical-record writing, diagnosis, prescribing, emergency triage and clinical decision-making are outside this service scope. Health correspondence must also be permitted under the applicable provider arrangements; human review does not override provider restrictions. Future clinical-record integrations require a separate scope assessment and agreement.
Only submit information necessary for the agreed purposes. Avoid unrelated sensitive information. Use synthetic or adequately anonymised examples in support requests where possible. Necessary patient information must use an approved support channel and remains subject to your instructions.
We do not sell Customer Personal Data, use it for advertising or train our own general-purpose AI models on it. Provider processing, including applicable security and abuse monitoring, is limited to the arrangements in Schedule 3. This DPA does not authorise unrelated provider use.
3. Confidentiality and security
We restrict access to authorised personnel who need it for the agreed purposes and are bound by confidentiality and appropriate instructions. Confidentiality continues for as long as the information remains protected.
We maintain technical and organisational measures appropriate to the processing risks, including the sensitivity of health information, as described in Schedule 2. We assess their effectiveness and do not materially reduce the agreed protection.
Routine development and testing use synthetic data; necessary support access is controlled and recorded.
4. Subprocessor authorisation
You give general written authorisation for the subprocessors identified in the agreed register under Schedule 3. We impose equivalent applicable data-protection obligations in writing and remain responsible for their performance as required by Article 28 GDPR and the SCCs.
We give at least 30 calendar days’ prior notice by email to your designated account contact of a proposed addition or replacement, including sufficient information to assess it. You may object on reasonable data-protection grounds during that period by contacting info@replygate.io. If an objection cannot be resolved, we will not assign the affected processing to that provider. The parties may discontinue the affected service under the agreement, subject to mandatory and SCC rights.
We provide the subprocessor and contractual information required by law and the SCCs, subject only to permitted redactions. Customer-contracted mailbox and integration providers are distinguished from subprocessors we appoint according to their actual roles.
5. International processing
TKM service and support locations: United Arab Emirates and Philippines, subject to the agreed confidentiality, security and transfer safeguards. Provider processing locations are described in Schedule 3.
Before a transfer requiring safeguards begins, the relevant instrument, transfer assessment and any necessary effective supplementary measures must be in place. Schedule 4 incorporates the applicable SCCs where their scope conditions are met. If the required protection cannot be ensured, affected processing will be suspended or ended as required.
We handle public-authority requests under applicable law and SCC duties, including notification, review, challenge and minimisation where required. General acceptance of this DPA does not replace assessment of an actual transfer.
6. Rights, incidents and assessments
Taking account of the processing, we assist you through appropriate technical and organisational measures, insofar as possible, with individuals’ data-protection requests. We promptly forward relevant requests and respond only on your instructions or as legally required.
We assist with security, breach notification, data protection impact assessments and prior consultation, taking account of the processing and information available to us. You remain responsible for your controller assessments; we retain our own duties.
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We provide available information about the breach, affected data and individuals, likely consequences, response measures and contact point. Further details may follow in phases without undue further delay. We investigate, contain, document and remediate the breach and cooperate with you.
7. Return and deletion
At the end of the processing services, we will, at your choice, return and then delete Customer Personal Data, or delete it, including copies, unless Union or Member State law requires storage. Applicable SCC return and deletion duties remain unaffected. Any permitted retained data remains protected and restricted to the preservation purpose.
Schedule 5 describes retention, return and deletion, including derived data and provider copies. Protected backups are excluded from ordinary use and expire under that schedule. Following restoration, outstanding deletion instructions are reapplied before the affected data returns to ordinary use. We confirm deletion on reasonable request and where the SCCs require it.
Account suspension does not remove your return or deletion rights. Separately justified billing or contract records must not include unnecessary patient content; our controller processing is explained in the Privacy Notice.
8. Accountability and changes
We provide information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by you or an authorised auditor as required by Article 28 GDPR and the SCCs. Reasonable arrangements for timing, confidentiality and other customers’ protection must not obstruct effective oversight, urgent investigations or regulatory access.
Material changes follow applicable notice and agreement requirements. Updating this webpage does not replace your accepted agreement. We retain prior versions and the agreement record; subprocessor changes follow section 4. Confidentiality, assistance and return/deletion obligations continue as applicable after termination.
Schedule 1. Parties and processing details
Customer identity: the company name and the representative’s name and email supplied at signup are retained with the acceptance record. Your company name must identify the legal organisation you represent. Required address/country, relevant organisation identifier and other party particulars are completed through the account or Order Form before the affected processing or transfer begins. The completed party and execution record is incorporated into this DPA and accessible to both parties; the initial signup record alone does not complete the SCC annexes. No separate clinic paper form is required.
TKM identity: TKM Group FZE, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates; trade licence 4203780.01. Responsible data-processing contact: Nicklas Christensen, info@replygate.io. For Module Two, the Customer is the data exporter and controller, and TKM is the data importer and processor. The incorporated party record completes SCC Annex I.A with named contacts, positions, contact details, relevant activities, roles, and both parties’ signatures or valid electronic execution details and dates. Applicable disclosure rights remain unaffected.
Purpose and operations: instructed correspondence and related CRM administration; receiving, organising, storing, retrieving and displaying content; processing relevant attachments; indexing or embedding where enabled; preparing drafts; editing and sending authorised replies; and instructed support, return and deletion.
Individuals: Customer personnel, contacts and correspondents; for clinics, patients, prospective patients and representatives, potentially including children and vulnerable people.
Data: names, contact details, message headers, bodies and history, relevant attachments, appointment information, instructed business context, drafts, replies and associated metadata, together with restricted connection credentials/tokens. Health information and other sensitive information may be present in correspondence. Processing is limited to what is necessary within the agreed scope and safeguards. For sensitive data, the purpose and support-channel restrictions in section 2 and the access, confidentiality, encryption, clinic-review and onward-processing safeguards in Schedules 2 and 3 apply.
Frequency and duration: ongoing while agreed features are enabled, for the service period and the return/deletion periods in Schedule 5. Mailboxes, folders, import history, attachments, features and authorised contacts are specified in account configuration before access. You act as controller and TKM as processor, subject to section 1.
Schedule 2. Security measures
Encryption: HTTPS with TLS 1.2 or later protects service connections. Database and file storage are encrypted at rest. Mailbox credentials and sensitive stored generation results are protected with application-managed cryptography, with access to the application and key material restricted. These measures do not constitute end-to-end encryption or zero knowledge.
Access: individual identities, password hashing, token validation, tenant isolation and role/permission checks restrict access. Privileged access requires multi-factor authentication. Access is authorised according to need, reviewed periodically and removed when no longer required.
Personnel and support: confidentiality obligations, security instructions and training apply to personnel with access. Support access is limited to the task, authorised and recorded. Work devices are protected against unauthorised access and kept updated. Routine testing uses synthetic data.
AI processing: inputs are limited to relevant content and configured context. Provider routing and permissions are controlled; the clinic workflow requires review before sending. AI-provider monitoring is governed by the arrangements in Schedule 3.
Resilience and erasure: protected backups support recovery. Recovery procedures, deletion and retry handling are tested proportionately to risk. Erasure includes derived content and is reapplied after restoration before ordinary use resumes.
Monitoring and assurance: security and diagnostic access is restricted; unnecessary message content is excluded from routine telemetry. Incidents are recorded and escalated to the responsible contact. Safeguards, vulnerabilities, access and supplier arrangements are reviewed periodically and following material changes.
Schedule 3. Subprocessors and locations
Before a subprocessor processes Customer Personal Data, we provide you with its legal identity, address, relevant contact details, processing purposes, duration and locations. That information forms part of the agreed, versioned subprocessor register available with your agreement. The service overview below does not replace those entity-specific particulars.
The Subprocessors page summarises each provider’s purpose, and its applicable version is retained with your acceptance record. Completed provider particulars must be provided before the affected processing begins. Listing a provider does not authorise purposes restricted by its terms, including restricted health-related use.
Microsoft Azure: customer content, files and operational data are processed for hosting, storage, backups, search, AI, document extraction, operational email and diagnostics. Primary application and storage resources are in Norway; selected AI and search resources are in Sweden. Global AI deployments, edge services and provider support may involve other countries; processing is not limited to the EEA.
Google Gemini Developer API Paid Services: selected message content, instructions, context and generated output are processed for permitted AI drafting and editing, including applicable security and abuse monitoring. Processing is international and is not limited to the EEA.
Apify Technologies s.r.o.: customer-selected website URLs, crawl metadata and extracted public content are processed for website import using US hosting and potentially other proxy locations. Do not import health or other special-category data unless expressly agreed in writing and permitted by the applicable provider terms.
Provider retention is service-specific. Applicable Gemini abuse monitoring may retain prompts, context and outputs for 55 days and permit authorised review and policy-enforcement-model use; it is distinct from general product/model improvement. Apify storage follows its applicable retention and deletion arrangements, including exceptions for named storage. These provider retention arrangements are separate from Replygate’s own backup retention.
Each provider processes data only for the enabled services, their duration and applicable return/deletion or limited retention arrangements. Provider agreements and required transfer safeguards apply to onward processing. Changes in provider identity, service or material processing arrangements follow this DPA’s notice and authorisation requirements.
A mailbox or integration provider you contract directly is identified through connection setup and assessed according to its actual role. Payment and website vendors are included as subprocessors under this DPA only if they process Customer Personal Data on our behalf, rather than separate controller data. Ordinary business email uses Namecheap Private Email with US hosting; patient information must use an approved support channel under section 2.
Schedule 4. Standard Contractual Clauses
For transfers within its scope, the applicable provisions of the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated without modification into this DPA. The SCCs form part of this agreement; a separate SCC acceptance is not required.
Module Two applies to an eligible controller-to-processor transfer. The optional docking clause applies. Clause 9(a) uses Option 2, general authorisation, with 30 calendar days’ prior notice. The optional independent dispute-resolution wording in Clause 11(a) does not apply. Clause 17 uses Option 1 and Danish law, which must allow the required third-party-beneficiary rights. Clause 18(b) selects the courts of Denmark without restricting Clause 18(c).
Annex I.A is completed by Schedule 1 and the incorporated party/execution record. Annex I.B is completed by Schedules 1, 2, 3 and 5 and the purpose and sensitive-data restrictions in section 2. For Annex I.C, the incorporated accepted record identifies the actual competent supervisory authority determined under Clause 13 for the exporter; for a Danish-established clinic exporter, this is Datatilsynet where Clause 13 so provides. Annex II is completed by Schedule 2. Annex III is not required under general authorisation; Schedule 3 and the incorporated register identify the subprocessors.
The official SCC text and the selections in this schedule are accessible and retained with the standard agreement. The completed party/execution record and applicable annexes must also be accessible and retained before a transfer relying on them begins. Only applicable clauses and options are incorporated. If Module Two is not applicable to a particular transfer, the appropriate alternative arrangement must be established before that transfer begins. A general reference to the SCCs does not dispense with scope, execution or assessment requirements.
Schedule 5. Retention, return and deletion
Live service content is retained while required to provide the agreed Service and follow your documented instructions, including earlier deletion instructions. At the end of processing, you choose return and deletion or deletion alone. We begin the instructed return or deletion without undue delay and provide a completion timetable taking account of the request’s scope and any shorter applicable legal or SCC requirement. Arranging that timetable does not authorise unnecessary retention or further use. Retention does not continue merely because an account is suspended.
Return covers Customer Personal Data in a commonly usable format through export or assisted delivery. Deletion covers live content, attachments, drafts, stored AI context, search indexes, embeddings, caches and queued processing. Connection credentials are revoked or removed when no longer needed. Completion is recorded and confirmed as required; permitted legal preservation is separately identified and restricted.
SQL point-in-time backups and blob/container soft-delete recovery copies follow a seven-day retention cycle. They are protected from ordinary use and expire after deletion reaches the relevant system. Restored content is subject to outstanding erasure instructions before ordinary processing resumes. Soft deletion alone is not treated as completed erasure.
Application diagnostic records are retained for up to 90 days for operation, security and investigation, subject to a documented necessary incident or legal hold. Routine diagnostics exclude unnecessary message content. Provider security/abuse-monitoring copies follow the service-specific periods and purposes identified in Schedule 3; these are distinct from Replygate’s own backups and live content.
Separately justified billing and contract records follow the Privacy Notice and do not include unnecessary patient content. We remain responsible for arranging required subprocessor assistance and for the return/deletion duties in this DPA and applicable SCCs.
For data-processing questions or requests, contact Nicklas Christensen at info@replygate.io.
